Accounts and privileges
A dedicated login for each application, personal logins for administrators, read-only logins for reports and analysis. The “sa” account and similar defaults are disabled or given a strong password kept in a safe place.
We cover Microsoft SQL Server, MySQL, MariaDB and PostgreSQL, on premises or in Azure, AWS and with European providers. Changes to databases behind packaged software are agreed with the vendor or software partner.
A dedicated login for each application, personal logins for administrators, read-only logins for reports and analysis. The “sa” account and similar defaults are disabled or given a strong password kept in a safe place.
The database is reachable only from the servers that use it. Maintenance by software partners goes through a VPN or jump host, not an open port.
Transparent data encryption or full-disk encryption, TLS between application and database, and encrypted backup files whose key is stored separately.
Recording sign-ins, privilege changes and reads of especially sensitive tables such as health or payroll data, forwarded to a central store so an intruder cannot wipe the evidence.
Cumulative and security updates for the database engine on a schedule that matches the software vendor’s approvals. Unsupported versions are flagged and an upgrade is planned.
Backups out of reach of ordinary users, one copy held in immutable storage, and a documented restore test in an isolated environment.
Databases carry the business, so nothing changes without a backup, agreement and a way back.
Which database instances exist, which versions, which applications depend on them and who has access. Forgotten test databases full of real customer records often turn up at this stage.
Configuration, accounts, network, encryption and backups are measured against recognised hardening guidance. You receive a ranked list of findings.
Changes during a maintenance window via remote access, coordinated with your software partner. Application logins are switched over without users noticing.
We restore a backup into a separate environment and time how long it takes. The result goes into your emergency documentation.
A backup that has never been restored is a hope, not a backup. Time and again we see damaged backup files, a missing key, or a restore that takes a day instead of an hour. You want to learn that during a drill, not on the morning the accounts department grinds to a halt.
Sometimes during installation and upgrades, rarely in day-to-day operation. We clarify with the vendor which rights are really needed and, if necessary, set up a separate upgrade login that is enabled only during maintenance.
The provider takes care of the operating system and engine patches. Logins, network rules, firewall settings, encryption keys and logs remain your responsibility, and that is exactly where we find most gaps in cloud databases.
From a GDPR perspective, yes, if there is no reason for it and it is less well protected than production. We help anonymise test data or generate synthetic data, and delete old copies once you approve.
At least twice a year and after any major change to the application or the backup tool. For critical systems we recommend a quarterly drill.
Tell us which database systems and applications you run. We will outline what a first assessment would cover.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.